Vulnerabilities > Deltascripts
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2006-10-10 | CVE-2006-5208 | SQL Injection vulnerability in Deltascripts PHP Classifieds 7.1 Multiple SQL injection vulnerabilities in PHP Classifieds 7.1 allow remote attackers to execute arbitrary SQL commands via (1) the catid_search parameter in search.php and (2) the catid parameter in index.php. | 7.5 |
2006-06-30 | CVE-2006-3330 | Input Validation vulnerability in Deltascripts PHP Classifieds 6.04 Cross-site scripting (XSS) vulnerability in AddAsset1.php in PHP/MySQL Classifieds (PHP Classifieds) allows remote attackers to execute arbitrary SQL commands via the (1) ProductName ("Title" field), (2) url, and (3) Description parameters, possibly related to issues in add1.php. network deltascripts | 6.8 |
2006-06-30 | CVE-2006-3329 | Input Validation vulnerability in Deltascripts PHP Classifieds 6.04 SQL injection vulnerability in search.php in PHP/MySQL Classifieds (PHP Classifieds) allows remote attackers to execute arbitrary SQL commands via the rate parameter. | 7.5 |
2006-06-07 | CVE-2006-2876 | Cross-Site Scripting vulnerability in PHP Pro Publish Cross-site scripting (XSS) vulnerability in cat.php in PHP Pro Publish 2.0 allows remote attackers to inject arbitrary web script or HTML via the catname parameter. network deltascripts | 6.8 |
2006-06-05 | CVE-2006-2821 | Cross-Site Scripting vulnerability in Deltascripts PRO Publish 2.0 Multiple cross-site scripting (XSS) vulnerabilities in DeltaScripts Pro Publish allow remote attackers to inject arbitrary web script or HTML via the (1) artid parameter in art.php and the (2) catname parameter in cat.php. network deltascripts | 6.8 |
2006-06-03 | CVE-2006-2803 | Cross-Site Scripting vulnerability in Deltascripts PHP Manualmaker 1.0 Multiple cross-site scripting (XSS) vulnerabilities in PHP ManualMaker 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) id parameter to index.php, (2) search field (possibly the s parameter), or (3) comment field. | 6.8 |
2006-05-01 | CVE-2006-2129 | SQL Injection vulnerability in Deltascripts PRO Publish 2.0 Direct static code injection vulnerability in Pro Publish 2.0 allows remote authenticated administrators to execute arbitrary PHP code by editing certain settings, which are stored in set_inc.php. | 5.5 |
2006-05-01 | CVE-2006-2128 | SQL Injection vulnerability in Deltascripts PRO Publish 2.0 Multiple SQL injection vulnerabilities in Pro Publish 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) email and (2) password parameter to (a) admin/login.php, (3) find_str parameter to (b) search.php, or (4) artid parameter to (c) art.php, or (5) catid parameter to (d) cat.php. | 7.5 |
2006-03-30 | CVE-2006-1532 | Cross-Site Scripting vulnerability in Deltascripts PHP Classifieds 6.18/6.20 Cross-site scripting (XSS) vulnerability in search.php in PHP Classifieds 6.18, 6.20, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the searchword parameter. network deltascripts | 4.3 |
2006-02-15 | CVE-2006-0719 | SQL Injection vulnerability in Deltascripts PHP Classifieds 6.18/6.19/6.20 SQL injection vulnerability in member_login.php in PHP Classifieds 6.18 through 6.20 allows remote attackers to execute arbitrary SQL commands via the (1) username parameter, which is used by the E-mail address field, and (2) password parameter. | 7.5 |